labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0-beta5之前版本存在服务端请求伪造漏洞,该漏洞源于共享SSRF保护仅验证初始请求URL,在将请求交由axios处理时未考虑其默认跟随重定向的行为,可能导致经过身份验证的工作流用户调用恶意URL重定向至云元数据、回环或内部服务,从而获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61644 | 7.7 HIGH | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text d |
| CVE-2026-61643 | 5.9 MEDIUM | FastGPT: workflow runtime can execute another user's private HTTP toolset |
| CVE-2026-61684 | FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default | |
| CVE-2026-50562 | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows |
No comments yet